About the job
DigitalOcean is hiring a Product Security Engineer in Bengaluru. This role focuses on solving large-scale security challenges while making it easier for engineering teams to build securely. The Security Engineering team works closely with other security groups and the wider DigitalOcean community to guide secure architecture, establish guardrails, and help engineers make informed security decisions. Security at DigitalOcean means tackling complex problems that affect customers, products, and the broader internet.
What you will do
- Assess security across infrastructure, applications, personnel, and processes.
- Work with product managers, designers, and engineers to model threats and design resilient systems.
- Review source code for secure coding practices and contribute to defining security requirements.
- Design and implement security services, tools, and libraries to promote secure defaults.
- Develop tools and services for engineers to support security in the CI/CD pipeline, such as custom Semgrep implementations and developer-first secrets management.
- Help build a platform that enables safe, straightforward, and low-risk software development at DigitalOcean.
- Promote internal security culture through developer training and internal Capture the Flag (CTF) events.
- Support engineers in understanding the impact of security events on their work, such as new CVEs or vulnerabilities like RetBleed.

